Product1 distinct publisher3 min readPublished
The CCPA access machinery companies have been building since 2020 just got a field test from one reporter with a spreadsheet. The failures cluster in support queue design rather than in the law itself.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The failure is in the routing. An access request and a deletion request come through the same inbox, get read by the same agent, and land in a ticket taxonomy where privacy is one bucket with one macro attached. Crunchbase told WIRED that its misclassified reply came from a person on its customer success team rather than a generative AI tool [8]. Crunchbase offered that as reassurance. It describes the harder version of the problem: a human read an email that said "I am not requesting deletion at this time" [6] and permanently deleted the account anyway [7].
Timing says the same thing. The request went out on August 17 and the deletion confirmation came back two days later [6][7]. CCPA gives companies 45 days to complete a request [3], which put the real deadline at October 1 [16]. The wrong answer cleared the queue after roughly 4 percent of the available window [15], so no lateness report was ever going to surface it.
BeenVerified failed differently. The reporter wrote to its dedicated CCPA compliance address on the morning of August 19 [9] and got back a note saying his person report had already been removed from Person Search results, along with the phone number and email address he had supplied [10]. When he clarified that he had asked for access, the reply 15 minutes later denied the claim and said the company could not verify his identity, in a thread where it had already located his details [11]. WIRED disclosed that the reporter used generative AI to draft his bureaucratic emails and maintain his tracking spreadsheet [14]. In these exchanges, the automated participant was the one that classified the request correctly.
McDonald's is the other kind of miss. It is the one product teams should recognize. The 515-page file described his app interactions in granular detail and included a prediction that he would never stop eating there [1]. That is a retention model delivered as a document dump. It is responsive to the statute and close to unusable for the person holding it. Ben Winters, director of AI and privacy at the Consumer Federation of America, told WIRED the handling of these requests was "crazy" and "not an acceptable status quo" [12].
Two axes are worth drawing over your own request flow: whether intake distinguishes access from deletion, and whether the first action an agent is able to take is reversible. Suppressing a listing from search results [10] sits in the recoverable half. Deleting an account the requester then has to register for again [7] does not. If your classification is weak, the cheap protection is making the default action reversible; if your defaults are destructive, the classification has to be right on the first read. Learning which cell you occupy costs an afternoon: someone outside the privacy function files a request from a personal address, and you look at what the first action taken was and whether anyone could undo it.
Ranked by verification strength, evidence, and original report placement.
A WIRED reporter filed a request with McDonald's earlier this month to access all personal data the company collected about him, and received a 515-page report a few days later detailing his app interactions in granular detail and predicting he would never stop eating there.
The California Consumer Privacy Act went into effect in 2020, and three of its key provisions are the right to opt out of the selling of personal information, the right to delete that information, and the right to request a copy for yourself.
After a CCPA request is submitted, companies can take 45 days to complete it.
The reporter spent the week after the McDonald's request filing more than 100 further requests, focused solely on access rather than deletion or opt-out, to understand what data is being collected.
Most companies must list two ways to file a request, often a web form, phone number, or email address, as designated in their privacy policy.
The reporter emailed his access request to Crunchbase's privacy address on August 17, stating: "I am not requesting deletion at this time. Please do not treat this as a deletion request."
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
Two social features, opposite results: a diet app trial argues against "add engagement"1 distinct publisher
invest
Legal tech's two leaders are buying the field, and nobody has disclosed a price1 distinct publisher
product
One suspension, four students, and an AI image nobody in the chain could delete1 distinct publisher
product
Proton's Yen stops refusing AI and ships Lumo, moving the privacy fight to terms1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documentary, and one desk deep
The spine of this is paper the reporter holds: an August 17 email with a written instruction not to delete, a support reply quoted in full that says the account is gone, a BeenVerified thread that contradicts itself inside 15 minutes, and named on-record responses from both companies rather than statements from unattributed spokespeople. What keeps it short of airtight is that WIRED is the only witness to its own inbox, and the two documented failures come out of a hundred-plus requests whose overall outcome is never tallied.
Machinery in daily use, quality unmeasured
Six years after the law took effect, the request rails plainly exist and carry traffic: one person pushed more than 100 requests through designated channels in a week, McDonald's returned 515 pages, and a UC Irvine researcher has run the same play at over 500 data brokers. Volume is not the question. What nobody in this reporting can state is the hit rate — how often a correctly framed access request comes back as access — and that is the number the story most needs.
Two queues asked to carry a system
The prose is disciplined — first person, dates, quotes, no claim that the law failed. The framing reaches further than the sample does: two detailed failures and a researcher's recollection are made to stand for how the whole apparatus behaves, while the reporter's own summary of the other hundred requests stays qualitative. The Crunchbase deletion is genuinely worse than the framing suggests, since it arrived after roughly four percent of the statutory window had run, so the overreach is in scope rather than severity.
Three parties, three convenient framings
Each account here is shaped by what its author needs to be true. Crunchbase's statement does two jobs at once — a 'processing error' by 'a person on our customer success team', with an unprompted denial that a generative model wrote the reply, which reads as getting ahead of a specific accusation. BeenVerified's counsel leads with the training that already existed and closes with more training, locating the fault in one agent. The Consumer Federation of America advocate is quoted precisely because these cases support the case for not relying on corporate good faith. WIRED's own incentive is the quest narrative, which it discloses partway by naming the generative AI it used for the bureaucratic email drafting.
Firm on the two cases, soft on the claim they support
That Crunchbase deleted an account it was asked not to touch, and that BeenVerified edited its index instead of answering, are as close to settled as single-outlet reporting gets — both companies said so themselves. Confidence drops on the conclusion the story is built around. Whether misclassification is the normal outcome or a bad tail depends on the ninety-eight requests we never see, and no regulator, dataset, or second newsroom is here to fill that in.